05 Apr Cash App notifies 8.2 million US customers about data breach Cash App is notifying 8.2 million current and former US customers of a data breach after a former employee accessed their account information. […]
05 Apr Chinese hackers abuse VLC Media Player to launch malware loader Security researchers have uncovered a long-running malicious campaign from hackers associated with the Chinese government who are using VLC Media Player to launch a custom malware loader. […]
05 Apr SpringShell attacks target about one in six vulnerable orgs Roughly one out of six organizations worldwide that are impacted by the Spring4Shell zero-day vulnerability have already been targeted by threat actors, according to statistics from one cybersecurity company. […]
04 Apr WhatsApp voice message phishing emails push info-stealing malware A new WhatsApp phishing campaign impersonating WhatsApp’s voice message feature has been discovered, attempting to spread information-stealing malware to at least 27,655 email addresses. […]
04 Apr GitHub can now auto-block commits containing API keys, auth tokens GitHub announced on Monday that it expanded its code hosting platform’s secrets scanning capabilities for GitHub Advanced Security customers to automatically block secret leaks. […]
04 Apr VMware patches Spring4Shell RCE flaw in multiple products VMWare has published a security advisory for the critical remote code execution vulnerability known as Spring4Shell, which impacts multiple of its cloud computing and virtualization products. […]
04 Apr Hackers breach MailChimp’s internal tools to target crypto customers Email marketing firm MailChimp disclosed on Sunday that they had been hit by hackers who gained access to internal customer support and account management tools to steal audience data and conduct phishing attacks. […]
03 Apr Fake Trezor data breach emails used to steal cryptocurrency wallets A compromised Trezor hardware wallet mailing list was used to send fake data breach notifications to steal cryptocurrency wallets and the assets stored within them. […]
03 Apr New Borat remote access malware is no laughing matter A new remote access trojan (RAT) named Borat has appeared on darknet markets, offering easy-to-use features to conduct DDoS attacks, UAC bypass, and ransomware deployment. […]
02 Apr UK charges two teenagers linked to the Lapsus$ hacking group Two teenagers from the UK charged with helping the Lapsus$ extortion gang have been released on bail after appearing in the Highbury Corner Magistrates Court court on Friday morning. […]